CVE-2026-1506

7.2

D-Link · DIR-615

D-Link DIR-615 firmware version 4.10 contains an OS command injection vulnerability in the MAC Filter Configuration component, reachable via the /adv_mac_filter.php file.

Executive summary

A remote OS command injection vulnerability in D-Link DIR-615 version 4.10 allows authenticated attackers to execute arbitrary system commands, posing a critical risk to device integrity.

Vulnerability

This flaw involves OS command injection (CWE-78) triggered through the manipulation of arguments in the /adv_mac_filter.php file. The attack requires high-level administrative privileges (PR:H) to reach the configuration endpoint.

Business impact

Successful exploitation allows an attacker to execute arbitrary OS commands with administrative privileges on the affected router. This could lead to full device compromise, unauthorized network access, and the potential for the device to be used as a pivot point for further attacks on the internal network. Given the CVSS score of 7.2, this represents a significant security risk for environments still utilizing this legacy hardware.

Remediation

Immediate Action: As the device is no longer supported by the vendor, the most effective remediation is to decommission the affected D-Link DIR-615 units and replace them with currently supported hardware.

Proactive Monitoring: Monitor network traffic for unusual outbound connections or attempts to access administrative interfaces from non-authorized internal segments.

Compensating Controls: Restrict access to the web-based management interface to a dedicated, isolated management VLAN or a specific trusted IP address to prevent unauthorized attempts at configuration manipulation.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the linked technical write-up.

Analyst recommendation

This vulnerability is particularly dangerous because the affected product has reached its end-of-life status and will not receive official security patches from D-Link. Organizations currently running D-Link DIR-615 version 4.10 must prioritize the immediate retirement and replacement of these devices to eliminate the risk of remote code execution. Continued use of this hardware exposes the network to persistent, unpatchable security threats.

More D-Link CVEs

Sources

Originally found and disclosed by Zephyr369 (VulDB User), per the CVE Program record.